Missed my #BHUSA talk on a security review on Signal E2EE messages βοΈπand vulnerabilities π?
The slides are now public!
Big thanks to Signal for their support during review π
www.ibrahim-elsayed.com/pdfs/US-25-E...
Posts by
And welcome to London π¬π§π
Let me know how it goes! Would love to try it once but the other way around :)
Positive Technologies published two scenarios they encountered during pentests, where they pivot to the internal network thanks to an Internet-facing Exchange server and its numerous SSRF vectors π
Happy birthday π
The court just handed WhatsApp a major win in the case against NSO Group βοΈ π
NSO was found liable under federal #CFAA & state law for #Pegasus hacking through WhatsApp's servers.
As a lawyer working on surveillance, let me break down the ruling π§΅ 1/
storage.courtlistener.com/recap/gov.us...
Many libraries and programmes support this environment variable by default :)
In 2024, we still have trivially exploitable Ubuntu LPE bugs π€·ββοΈ
But one of the disclosed bugs involves the good old pipe character in Perl "filenames" π€―
Another great investigation by the Qualys Threat Research Unit π
admin:admin